Legal
Privacy Policy
Last updated: 14 Aug 2026
This privacy notice for Workestic (“we,” “us,” or “our”) describes how we collect, use, store, and share information when you use Workestic Drive Exporter, our Stripe Dashboard app, and our website at workestic.com (collectively, the “Services”).
Questions? Contact us at support@workestic.com.
Summary of key points
- Stripe export data is not stored. Export payloads pass through our API in memory only long enough to create your Google Sheet.
- We store only data needed to operate the integration: account-scoped connections and settings, limited export-result metadata, billing state, and saved automation definitions when that feature is enabled—not exported Stripe row contents.
- Google user data is used only to provide the app: create Sheets in the app-created Stripe Exports folder in your Drive. We do not sell personal information.
- You can disconnect or uninstall to delete stored account data. See Data retention and deletion.
- Depending on where you live, you may have rights to access, correct, or delete personal information. See Your privacy rights.
1. What information do we collect?
Information you provide through the App
When you onboard Workestic Drive Exporter and connect Google Drive, we process information needed to operate the service:
-
Stripe account ID (
acct_…): to identify your installation and enforce plan limits - Google OAuth refresh token: encrypted at rest in Postgres (Neon), keyed per Stripe account, so you do not re-authenticate every export
- Google account email: to show connection status in the App and, only when paid scheduling is enabled, deliver operational schedule-failure alerts
- Export folder reference: the app-created Stripe Exports folder in Google Drive
- Operational usage totals: aggregate counts such as completed exports and source rows
- Recent export metadata: report label, row and column counts, Sheet URL or file reference, filename, and completion timestamp, but not exported row contents
- Plan and billing state: plan, subscription status, renewal/end date, cancellation state, grace dates, and Stripe Customer, Subscription, and Price identifiers
- Billing identity handled by Stripe: hosted Checkout collects the billing name and address and, when supplied by a business buyer, a tax ID for tax and invoice purposes. Stripe stores those details; Workestic stores the Stripe identifiers and billing state described above, not a copy of the billing address or tax ID
- Chrome companion data when enabled: hashed session and pairing tokens, saved sync definitions, schedule/run status, encrypted Stripe restricted read key, and the key's non-secret last four characters
- Failure-notification state when enabled: an account and saved-sync reference, random incident and idempotency IDs, retry count, safe error category, provider message ID, and delivery status. We do not store the recipient address, subject, or message body in the notification outbox.
Information processed during exports (not stored)
When you run an export, Stripe business data (for example customers, payments, or invoices) is read in your browser using Stripe’s platform authentication, sent to our API, and used in memory to create a Google Sheet. We do not persist export payloads. See Stripe data: transit only.
Payment information
If you purchase a paid plan, payment processing is handled by Stripe. We do not store full payment card numbers. Stripe’s privacy policy applies to payment data: stripe.com/privacy.
Information collected automatically
When you visit our website or use our API, our hosting providers may automatically collect limited technical information such as IP address, browser type, device characteristics, referring URL, and timestamps in server logs. We use Google Analytics on our marketing site to understand page views, traffic sources, scrolls, and outbound clicks so we can improve the website and SEO. Secure upgrade tokens, Checkout references, Stripe account IDs, and user IDs are removed from the URL before analytics initializes and are not included in analytics events. Google Analytics may set cookies or similar identifiers in your browser.
Sensitive information
We do not intentionally collect sensitive personal information.
2. How do we process your information?
We process personal information to:
- Provide, operate, and maintain Workestic Drive Exporter
- Authenticate your Stripe installation and Google connection
- Create Google Sheets in the app-created Stripe Exports folder
- Enforce plan limits and prevent abuse
- Process opt-in subscriptions through Stripe Checkout and Customer Portal when billing is enabled
- Run saved schedules only when paid automation and the verified account entitlement are enabled
- Send one generic operational email for the first failure in a consecutive schedule-failure incident
- Respond to support requests and communicate about the Services
- Comply with legal obligations and protect our rights
- Improve reliability and security of the Services
We do not use Google user data for advertising, sell personal information, or use it for purposes unrelated to providing the App feature you requested.
3. Stripe data: transit only
We do not store Stripe customer records, invoice rows, payment amounts, or any export payload in our database. Stripe data passes through our backend in memory only long enough to write your Google Sheet, then is discarded. We keep limited result metadata described above and structured operational error categories, not request body contents, raw provider errors, access keys, or exported row data.
4. Google user data
With your consent, we use Google OAuth scopes to create Sheets in the app-managed Stripe Exports folder in your Drive. We do not browse your Drive folders, and we do not read or store the contents of your existing Drive files.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Legal bases (EEA, UK, and Switzerland)
If you are in the EEA, UK, or Switzerland, we rely on the following legal bases:
- Performance of a contract: to provide the App, store settings, and process exports you request
- Consent: when you connect Google Drive and authorize OAuth scopes
- Legitimate interests: to secure the Services, prevent abuse, enforce plan limits, and improve reliability, balanced against your rights
- Legal obligation: where required to comply with applicable law
You may withdraw consent for Google connection at any time by disconnecting Google Drive in App settings.
6. When and with whom we share information
We share information only as needed to operate the Services:
-
Service providers (subprocessors): companies that host or support our
infrastructure:
- Google Cloud Run: hosts our API (
api.workestic.com) - Neon: Postgres database for account-scoped settings, encrypted tokens, billing state, saved syncs, limited result metadata, and anonymous aggregate counters
- Google: OAuth, Drive, and Sheets APIs
- Stripe: Dashboard app platform, install context, and billing
- Netlify: hosts this website (
workestic.com) - Cloudflare: DNS and email routing for our domain
- Resend: delivers operational schedule-failure emails. Resend receives the connected Google email address and generic alert content only when an alert is sent; no Stripe row data, export name, filename, account ID, or raw provider error is included.
- Google Cloud Run: hosts our API (
- Legal and safety: if required by law, court order, or to protect rights, safety, and security
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this privacy notice
We have not sold or shared personal information for cross-context behavioral advertising in the preceding twelve (12) months. We do not sell personal information.
7. Data retention and deletion
We retain account settings and encrypted credentials while the relevant connection and installation are active and as needed to provide the Services. When you disconnect Google Drive in App settings, we revoke the token at Google and delete the stored Google connection. When you uninstall the App from Stripe, we delete or de-identify associated operational account data, including credentials, settings, saved syncs, recent export metadata, and account-linked telemetry. Merchant-owned Google Sheets remain in the user's Drive.
We retain anonymous daily trend counts without an account or user identifier so we can see aggregate product reliability over time. Raw product click events are not retained after the anonymous daily counter is updated. Short-lived random event IDs may be held for up to seven days only to prevent duplicate counting. Application logs are normally retained for 30 days and contain structured error categories and pseudonymous correlation keys rather than raw account/user IDs, URLs, filenames, tokens, or payloads. Billing records may remain with Stripe, or be retained where tax, accounting, fraud-prevention, or other law requires it. Backup copies may persist for a short period before being overwritten.
Detailed failure-notification and webhook-deduplication records are deleted after 30 days; only anonymous daily trend counts remain. Disconnecting Google removes the stored recipient address and prevents pending alerts from being delivered. Uninstalling the App deletes the account-scoped notification outbox through database cascade rules. Resend may retain delivery records under its own privacy policy and account settings.
To request deletion of personal information we hold, email support@workestic.com or see Your privacy rights.
8. How we keep your information safe
We use organizational and technical measures designed to protect personal information, including HTTPS in transit, encryption at rest for OAuth tokens, access controls, and least-privilege infrastructure design. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
9. International transfers
We and our subprocessors may process information in the United States and other countries. If you access the Services from outside the United States, your information may be transferred to and processed in the United States. Where required, we rely on appropriate safeguards such as standard contractual clauses.
10. Your privacy rights
Depending on your location, you may have the right to request access, correction, deletion, restriction, or portability of your personal information, and to object to or withdraw consent for certain processing. We will respond to verified requests in accordance with applicable law.
To exercise your rights, contact support@workestic.com. We may need to verify your identity before processing a request. You may also use our support page.
EEA and UK
If you believe we are unlawfully processing your personal information, you may lodge a complaint with your local data protection authority.
United States residents
Residents of California, Colorado, Connecticut, Utah, Virginia, and other states with privacy laws may have additional rights, including the right to know what personal information we collect, request deletion, and opt out of certain processing. We do not sell personal information or use it for targeted advertising.
Categories we may collect include:
- Identifiers: Stripe account ID, Google email, IP address in logs
- Internet or network activity: App and API usage metadata, server logs
- Commercial information: plan tier and billing status (if you subscribe)
We use this information only to provide and improve the Services as described in this notice. We will not discriminate against you for exercising privacy rights.
California residents may contact the California Attorney General or, for unresolved complaints, the Complaint Assistance Unit of the Division of Consumer Services of the California Department of Consumer Affairs.
11. Minors
The Services are intended for users at least 18 years old. We do not knowingly collect personal information from children under 18. If you believe we have collected such information, contact us and we will delete it.
12. Do-not-track
Some browsers offer a Do-Not-Track (“DNT”) signal. There is no uniform standard for responding to DNT signals. We do not currently respond to DNT browser signals.
13. Updates to this notice
We may update this privacy notice from time to time. The updated version will be indicated by an updated “Last updated” date. Material changes will be posted on this page. We encourage you to review this notice periodically.
14. Contact us
If you have questions about this privacy notice or our privacy practices, contact us at support@workestic.com.